Select your cookie preferences

We use cookies and similar tools to enhance your experience, provide our services, deliver relevant advertising, and make improvements. Approved third parties also use these tools to help us deliver advertising and provide certain site features.

CVE-2023-6817

Public on 2023-12-18
Modified on 2024-01-11
Description

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.

The function nft_pipapo_walk did not skip inactive elements during set walk which could lead double deactivations of PIPAPO (Pile Packet Policies) elements, leading to use-after-free.

We recommend upgrading past commit 317eb9685095678f2c9f5a8189de698c5354316a.

Severity
Important
See what this means
CVSS v3 Base Score
7.8
See breakdown
Continue reading

Affected Packages

Platform Package Release Date Advisory
Amazon Linux 2 - Kernel-5.10 Extra kernel 2024-01-05 21:40 ALAS2KERNEL-5.10-2024-045
Amazon Linux 2 - Kernel-5.10 Extra kernel 2024-01-19 02:20 ALAS2KERNEL-5.10-2024-047
Amazon Linux 2 - Kernel-5.15 Extra kernel 2024-01-05 21:40 ALAS2KERNEL-5.15-2024-033
Amazon Linux 2 - Kernel-5.15 Extra kernel 2024-01-19 02:20 ALAS2KERNEL-5.15-2024-035
Amazon Linux 2023 kernel 2024-01-19 01:31 ALAS2023-2024-488
Amazon Linux 2 - Livepatch Extra kernel-livepatch-5.10.201-191.748 2024-02-29 00:57 ALAS2LIVEPATCH-2024-167

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NVD CVSSv3 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H